The420.In
Evasive Panda APT Uses DNS Poisoning to Deploy MgBot Malware in Targeted Attacks
First seen 1 Jan 2026, 08:19 UTC
•

•74% similarity
•52.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The China-linked APT group Evasive Panda has conducted cyber-espionage campaigns using DNS poisoning to install the MgBot backdoor. Targeted victims include entities in Türkiye, China, and India. Kaspersky researchers have identified this group, also known by several other names, as responsible for these attacks.
ThreatCluster AI